Incident Response Engineer
remote
Job Id:
0000175966
Job Category:
Cyber Security
Job Location:
remote
Security Clearance:
No Clearance
Business Unit:
Piper Companies
Division:
Not Defined
Position Owner:
Jacqueline Norsworthy
Piper Companies is seeking an Incident Response Engineer to join a leading cybersecurity-focused organization. The Incident Response Engineer will play a critical role in detecting, investigating, and responding to security incidents across complex enterprise environments. This position is ideal for a security professional with deep expertise in incident response, threat hunting, UEBA platforms, and advanced Splunk analytics.
Responsibilities of the Incident Response Engineer:
• Investigate, analyze, and respond to cybersecurity incidents across endpoints, networks, cloud environments, and enterprise applications.
• Perform proactive threat hunting activities to identify indicators of compromise, malicious behavior, and emerging threats.
• Utilize UEBA platforms to detect anomalous user and entity behavior and validate potential security events.
• Develop and optimize SPL queries, dashboards, alerts, and reports within Splunk to improve detection capabilities.
• Conduct detailed forensic investigations and root cause analysis following security incidents.
• Collaborate with CSIRT, SOC, and engineering teams to coordinate effective incident response efforts.
• Create and maintain incident response playbooks, procedures, and documentation.
• Provide recommendations for security improvements based on investigation findings and threat intelligence.
Qualifications of the Incident Response Engineer:
• 5+ years of cybersecurity experience with a focus on incident response and threat investigations.
• Strong hands-on experience with Splunk, including advanced SPL querying, dashboard creation, and detection engineering.
• Experience working with UEBA solutions and behavioral analytics platforms.
• Proven expertise in threat hunting methodologies and investigation techniques.
• Experience supporting or operating within a CSIRT environment.
• Knowledge of endpoint, network, cloud, and identity-based attack vectors.
• Familiarity with SIEM technologies, digital forensics, malware analysis, and threat intelligence processes.
• Strong analytical, communication, and documentation skills.
• Relevant certifications such as GCIH, GCFA, GCIA, CISSP, or equivalent are preferred.
Compensation for the Incident Response Engineer includes:
• Salary range: $130,000 - $160,000 depending on experience
• Comprehensive benefits package including medical, dental, vision, 401(k), and PTO
This job opens for applications on 10/06/2026. Applications for this job will be accepted for at least 30 days from the posting date.
#LI-JN1
#LI-REMOTE